Cloud Network Anomaly Detection via Dynamic Behavioral Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity measures in cloud environments struggle to dynamically and automatically adapt to changing attack vectors and targets, particularly in complex and ever-changing environments where traditional security features like micro-segmentation and cloud-provider security groups cannot prevent abuse of permitted connections by external attackers or internal threats.

Innovation Solution

A method and system for detecting anomalous network activity using probabilistic unsupervised learning methods, which create and continuously update profiles of virtual entities' network behavior, allowing for the identification of deviations from expected behavior and potential security incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security features like micro-segmentation and cloud-provider security groups are used, then network connection control between workloads is improved, but the system cannot stop abuse of permitted connections by external attackers or internal threats

Engineering Contradiction:
Improvenetwork connection controlVSAvoidability to stop abuse of permitted connections
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic baseline adjustment by continuously learning normal network behavior patterns from multiple sources (on-premises, cloud, hybrid environments) and adapting security policies in real-time. The system updates baselines based on changing organizational needs, seasonal patterns, and emerging threat landscapes, transforming static security groups into dynamic, adaptive security boundaries that automatically respond to abnormal behaviors while maintaining permitted connections.

Inventive Principle:
Principle #15Dynamics

2Reliability

If policies-enforcing security features are implemented to limit network connections, then security control is improved, but complex and ever-changing attack vectors cannot be dynamically adapted to

Engineering Contradiction:
Improvesecurity controlVSAvoiddynamic adaptation to changing attack vectors
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements comprehensive feedback loops by continuously monitoring network traffic, comparing observed behaviors against learned baselines, and automatically adjusting security policies based on detected anomalies. The system incorporates feedback from multiple environments (on-premises, cloud, hybrid) and uses machine learning to refine its understanding of normal versus abnormal behavior, enabling dynamic adaptation to new attack vectors while maintaining security control.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary action by proactively learning and establishing baselines of normal network behavior before attacks occur. The system continuously ingests data from various sources, pre-processes and normalizes information, and builds predictive models of expected behavior patterns. This preliminary preparation enables the system to quickly detect and respond to deviations from normal behavior, allowing dynamic adaptation to new attack vectors without waiting for incidents to occur.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If traditional security protection methods are used, then established security boundaries are maintained, but rapid and automatic adaptation to changing attack vectors and targets is not achieved

Engineering Contradiction:
Improvesecurity boundariesVSAvoidspeed of adaptation to changing threats
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The patent implements parameter changes by dynamically adjusting security policy parameters based on learned behavioral patterns and detected anomalies. The system modifies connection allowances, rate limits, and access rules in real-time based on changing threat landscapes and organizational needs. This enables rapid adaptation to new attack vectors while maintaining stable security boundaries through controlled, data-driven parameter adjustments rather than rigid static configurations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250150347A1Multi-baseline unsupervised security-incident and network behavioral anomaly detection in cloud-based compute environments
Publication Date: 2025.05.08 INTSIGHTS CYBER INTELLIGENCE LTD
  • US20250150347A1 patent drawing
  • US20250150347A1 patent drawing
  • US20250150347A1 patent drawing

AI summary

A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.